IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1)
IAEA NSS-17 Scope + CSP Establishment

IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1) IAEA-NSS17-Scope-NSS-Family-CSP-Establishment: IAEA NSS-17 + NSS-42-G - Scope + Nuclear Security Series Family + Computer Security Programme Establishment + Roles + Management System Integration

IAEA Nuclear Security Series (NSS) is the family of publications providing internationally agreed guidance on nuclear security developed in consultation with Member States. NSS-17 Computer Security at Nuclear Facilities (Technical Guidance Reference Manual, original December 2011) was the foundational Implementing Guide; superseded by NSS-17-T Rev 1 modernisation and complemented by NSS-42-G Computer Security for Nuclear Security (Implementing Guide, 2021) which expanded scope beyond facilities to cover the full nuclear security regime including material in transport + radioactive sources + material out of regulatory control. NSS family categories: Nuclear Security Fundamentals (objectives + concepts + principles); Recommendations (best practices for Member States); Implementing Guides (further elaboration of Recommendations); Technical Guidance (Reference Manuals + Training + Service Guides). NSS-17/42-G apply to: national authorities + operators of nuclear facilities (Nuclear Power Plants NPPs + research reactors + fuel cycle facilities) + radioactive material associated facilities + material out of regulatory control. Computer Security Programme (CSP) establishment: senior management commitment + dedicated computer security function + competent authority designation + reporting line to senior management; policy statement + objectives + scope + commitment to continuous improvement; integration with overall facility management system (Quality + Safety + Physical Security + Emergency Preparedness + Information Security per NSS-23-G); roles + responsibilities + competencies + RACI for: operator + State + Regulatory Body + designated competent authority + national CSIRT + intelligence + law enforcement + IAEA. Coordinates with International Convention on Physical Protection of Nuclear Material amended (CPPNM/A) + Code of Conduct on Safety and Security of Radioactive Sources + UNSCR 1373 + UNSCR 1540 + International Convention for the Suppression of Acts of Nuclear Terrorism. IAEA NSS-17 + NSS-42-G + Computer Security Programme + management system + roles applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 21 controls across 15 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 3 controls

ISO/IEC 27011:2024 · 2 controls

  • 27011-7.1 Physical security perimeters
  • 27011-7.3 Equipment protection
  • 58.43 Animal Care Facilities
  • AT-DSG-6 Sections 12-13 - Image processing (video surveillance/CCTV)
  • CJIS-14 Physical Protection
  • ISO28001-PS-01 Facility Security

ISO/IEC 27010:2015 · 1 control

  • 27010-11.1 Physical Protection

ISO/IEC 27400:2022 · 1 control

  • 27400-5.2 IoT Risk Assessment
  • NAIC-2 Information Security Program (ISP) - Section 4
  • NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
  • NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access
  • PSPF24-4 Physical Security
  • USMTSA-1 Facility Security Assessment and Plan

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 21 it maps to, and the evidence behind each claim, over MCP and REST.